{"_id":"@akeyless-community/digitalocean-runtime","name":"@akeyless-community/digitalocean-runtime","dist-tags":{"latest":"0.1.0"},"versions":{"0.1.0":{"name":"@akeyless-community/digitalocean-runtime","version":"0.1.0","description":"Fetch Akeyless secrets at runtime on DigitalOcean App Platform (Node.js) — no env-var sync required","license":"Apache-2.0","author":{"name":"Akeyless Community"},"repository":{"type":"git","url":"git+https://github.com/akeyless-community/digitalocean-runtime.git"},"homepage":"https://github.com/akeyless-community/digitalocean-runtime#readme","keywords":["akeyless","digitalocean","app-platform","secrets","runtime","environment-variables","paas"],"engines":{"node":">=18"},"main":"./dist/index.js","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"}},"scripts":{"build":"tsc -p tsconfig.json","test":"node --experimental-vm-modules node_modules/jest/bin/jest.js","prepublishOnly":"npm run build && npm test","example:install":"npm run build && cd examples/express && npm install","example:start":"npm run example:install && cd examples/express && npm start"},"publishConfig":{"access":"public"},"dependencies":{"akeyless":"^5.0.25","akeyless-cloud-id":"^1.0.0"},"devDependencies":{"@types/jest":"^29.5.14","@types/node":"^20.17.0","jest":"^29.7.0","ts-jest":"^29.2.5","typescript":"^5.7.2"},"gitHead":"0a15f502d4c54c734e0686632bc74b849c0ebd1a","_id":"@akeyless-community/digitalocean-runtime@0.1.0","bugs":{"url":"https://github.com/akeyless-community/digitalocean-runtime/issues"},"_nodeVersion":"26.3.0","_npmVersion":"11.16.0","dist":{"integrity":"sha512-nna6xJKEbm5IEmNNJYcldZKYBdckhztS5VIKgaXIxxaxYSlJIq0gFt1wFD7BHpsav3ij9/hC80lY5mEtevqHVg==","shasum":"72a1b3dfd9e7c0268cd99dc9363bba904362aa48","tarball":"https://registry.npmjs.org/@akeyless-community/digitalocean-runtime/-/digitalocean-runtime-0.1.0.tgz","fileCount":31,"unpackedSize":74715,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQCc7d1dpBhbt4R+CNjLVy6MejTYQsy7tnIjLHr+TJfEgAIhAOL+NU1lxQ/jt9x/XhrzIG10QOskanVqXgMGYlPtoXt+"}]},"_npmUser":{"name":"barak-akeyless","email":"barak.a@akeyless.io"},"directories":{},"maintainers":[{"name":"barak-akeyless","email":"barak.a@akeyless.io"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/digitalocean-runtime_0.1.0_1781519030334_0.21398850237217792"},"_hasShrinkwrap":false}},"time":{"created":"2026-06-15T10:23:50.133Z","0.1.0":"2026-06-15T10:23:50.471Z","modified":"2026-06-15T10:23:50.725Z"},"maintainers":[{"name":"barak-akeyless","email":"barak.a@akeyless.io"}],"description":"Fetch Akeyless secrets at runtime on DigitalOcean App Platform (Node.js) — no env-var sync required","homepage":"https://github.com/akeyless-community/digitalocean-runtime#readme","keywords":["akeyless","digitalocean","app-platform","secrets","runtime","environment-variables","paas"],"repository":{"type":"git","url":"git+https://github.com/akeyless-community/digitalocean-runtime.git"},"author":{"name":"Akeyless Community"},"bugs":{"url":"https://github.com/akeyless-community/digitalocean-runtime/issues"},"license":"Apache-2.0","readme":"# @akeyless-community/digitalocean-runtime\n\nFetch [Akeyless](https://www.akeyless.io) secrets at **runtime** on [DigitalOcean App Platform](https://www.digitalocean.com/products/app-platform) (Node.js). Application secrets stay in Akeyless — only bootstrap auth variables are stored on DigitalOcean.\n\n**Repository:** [github.com/akeyless-community/digitalocean-runtime](https://github.com/akeyless-community/digitalocean-runtime)\n\n## Install\n\n```bash\nnpm install @akeyless-community/digitalocean-runtime\n```\n\nRequires **Node.js 18+**.\n\n## Quick start\n\n### 1. Set bootstrap variables on App Platform\n\nIn your component **Environment Variables** (runtime scope), add read-only Akeyless credentials:\n\n| Variable | Required | Example |\n|----------|----------|---------|\n| `AKEYLESS_ACCESS_ID` | Yes* | `p-xxxxx` |\n| `AKEYLESS_ACCESS_KEY` | Yes* | access key secret |\n| `AKEYLESS_SECRET_PREFIX` | Recommended | `/digitalocean/my-app/production` |\n| `AKEYLESS_GATEWAY_URL` | No | `https://api.akeyless.io` |\n\n\\* Or use another [auth method](#authentication) below.\n\n**Bindable variables for prefix derivation** — App Platform does not inject these automatically; add them as runtime variables using [bindable references](https://docs.digitalocean.com/products/app-platform/how-to/use-environment-variables/):\n\n| Variable | Value (bindable) | Purpose |\n|----------|------------------|---------|\n| `APP_DOMAIN` | `${APP_DOMAIN}` | Human-readable app slug for secret paths |\n| `APP_ID` | `${APP_ID}` | Fallback app identifier |\n| `AKEYLESS_ENV` | `production` (or `staging`, etc.) | Environment segment in paths |\n\nIf `AKEYLESS_SECRET_PREFIX` is omitted, the library derives it from:\n\n```\n/digitalocean/{APP_DOMAIN or APP_ID}/{AKEYLESS_ENV}\n```\n\nSet `AKEYLESS_APP_NAME` to override the app segment when your domain is not ideal for paths.\n\n### 2. Store application secrets in Akeyless\n\n```\n/digitalocean/my-app/production/DATABASE_URL\n/digitalocean/my-app/production/STRIPE_SECRET_KEY\n```\n\nFor multi-component apps, opt into per-component prefixes:\n\n```bash\nDO_COMPONENT_NAME=web\nAKEYLESS_INCLUDE_COMPONENT_IN_PREFIX=true\n# → /digitalocean/my-app/production/web/DATABASE_URL\n```\n\n`DO_COMPONENT_NAME` should match the `name` field of your service/worker in the app spec.\n\n### 3. Fetch secrets in your app\n\n```javascript\nconst express = require('express');\nconst { getSecret } = require('@akeyless-community/digitalocean-runtime');\n\nconst app = express();\n\napp.get('/health', async (_req, res) => {\n  const dbUrl = await getSecret('DATABASE_URL');\n  res.json({ ok: true, hasDb: Boolean(dbUrl) });\n});\n\napp.listen(process.env.PORT || 8080);\n```\n\nUse `getSecret` only in **server** code. Never expose fetched secrets to the browser.\n\n## App spec example\n\n```yaml\nname: my-app\nservices:\n  - name: web\n    github:\n      repo: your-org/your-repo\n      branch: main\n    envs:\n      - key: AKEYLESS_ACCESS_ID\n        scope: RUN_TIME\n        value: p-xxxxx\n      - key: AKEYLESS_ACCESS_KEY\n        scope: RUN_TIME\n        type: SECRET\n        value: your-access-key\n      - key: APP_DOMAIN\n        scope: RUN_TIME\n        value: ${APP_DOMAIN}\n      - key: AKEYLESS_ENV\n        scope: RUN_TIME\n        value: production\n```\n\n## Per-environment prefixes\n\nDigitalOcean does not provide a built-in environment tier name. Set `AKEYLESS_ENV` per deployment (or use separate apps):\n\n| Deployment | `AKEYLESS_ENV` | Typical prefix |\n|------------|----------------|----------------|\n| Production | `production` | `/digitalocean/my-app/production` |\n| Staging | `staging` | `/digitalocean/my-app/staging` |\n\nSet `AKEYLESS_SECRET_PREFIX` explicitly when you need a custom layout.\n\n## API\n\n### Convenience (singleton, container-friendly)\n\n```javascript\nconst { getSecret, getDefaultClient } = require('@akeyless-community/digitalocean-runtime');\n\nconst dbUrl = await getSecret('DATABASE_URL');\n```\n\n### Explicit client\n\n```javascript\nconst { createClient } = require('@akeyless-community/digitalocean-runtime');\n\nconst client = createClient({\n  gatewayUrl: 'https://api.akeyless.io',\n  secretPrefix: '/digitalocean/my-app/production',\n  accessId: process.env.AKEYLESS_ACCESS_ID,\n  accessKey: process.env.AKEYLESS_ACCESS_KEY,\n});\n\nawait client.getSecret('DATABASE_URL');\nawait client.getSecretAtPath('/custom/full/path');\nawait client.getDynamicSecret('db-creds');\nawait client.getRotatedSecret('rotated-api-key');\n```\n\n## Authentication\n\nConfigure via App Platform environment variables or `createClient({ ... })`.\n\n| Method | `AKEYLESS_ACCESS_TYPE` | Additional variables |\n|--------|------------------------|----------------------|\n| Access key (default) | `access_key` | `AKEYLESS_ACCESS_ID`, `AKEYLESS_ACCESS_KEY` |\n| API key | `api_key` | `AKEYLESS_ACCESS_ID`, `AKEYLESS_ACCESS_KEY` |\n| Universal Identity | `universal_identity` | `AKEYLESS_UID_TOKEN` |\n| JWT | `jwt` | `AKEYLESS_ACCESS_ID`, `AKEYLESS_JWT` |\n| AWS IAM | `aws_iam` | `AKEYLESS_ACCESS_ID`, optional `AKEYLESS_CLOUD_ID` |\n| Pre-authenticated | — | `AKEYLESS_TOKEN` |\n\nUse a dedicated Akeyless auth method with **read-only** access to your `/digitalocean/...` path.\n\n## Local development\n\nExport the same variables you use on App Platform:\n\n```bash\nexport AKEYLESS_ACCESS_ID=p-xxxxx\nexport AKEYLESS_ACCESS_KEY=your-key\nexport AKEYLESS_APP_NAME=my-app\nexport AKEYLESS_ENV=development\nexport AKEYLESS_SECRET_PREFIX=/digitalocean/my-app/development\n```\n\nOr use [doctl apps dev](https://docs.digitalocean.com/reference/doctl/reference/apps/dev/) when available in your workflow.\n\n## Caching\n\n- **Auth tokens** refresh before expiry (default margin: 1 minute).\n- **Secret values** cache in memory for **5 minutes** by default (`AKEYLESS_SECRET_CACHE_TTL_MS`).\n- Long-lived containers reuse the module singleton.\n\nLower TTL or use `ignoreCache: true` for frequently rotated secrets.\n\n## Push sync vs runtime pull\n\n| Pattern | When to use |\n|---------|-------------|\n| **Runtime pull** (this package) | Akeyless stays source of truth; only bootstrap creds on App Platform |\n| **Push sync** | Copy secrets into App Platform variables (future Akeyless Destination Sync or CI) |\n\nRuntime pull works today without a DigitalOcean marketplace listing.\n\n## Example app\n\n```bash\nnpm run build\ncd examples/express && npm install\nnpm start\n```\n\nSet `AKEYLESS_*` env vars before starting.\n\n## Publishing\n\nThis package is Apache-2.0 and published as `@akeyless-community/digitalocean-runtime` on npm.\n\n```bash\nnpm ci\nnpm test\nnpm publish --access public\n```\n\n## Related community projects\n\n- [@akeyless-community/railway-runtime](https://github.com/akeyless-community/railway-runtime) — Railway runtime secrets\n- [@akeyless-community/fly-runtime](https://github.com/akeyless-community/fly-runtime) — Fly.io runtime secrets\n- [@akeyless-community/vercel-runtime](https://github.com/akeyless-community/vercel-runtime) — Vercel runtime secrets\n- [@akeyless-community/netlify-runtime](https://github.com/akeyless-community/netlify-runtime) — Netlify runtime secrets\n- [@akeyless-community/heroku-runtime](https://github.com/akeyless-community/heroku-runtime) — Heroku runtime secrets\n\n## License\n\nApache-2.0\n","readmeFilename":"README.md","_rev":"1-8617042498901b761a7bc869214175cc"}